CISSP Security Assessment and Testing Practice Question
A security manager is reviewing metrics and sees that the "mean time to remediate" for critical vulnerabilities has increased over the past quarter. This metric is an example of a:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Key Performance Indicator (KPI)
Mean time to remediate is a Key Performance Indicator (KPI) used to measure the effectiveness of vulnerability management processes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security baseline
Why it's wrong here
A security baseline defines the minimum set of security controls, configurations, and practices that must be implemented across systems or organizations to achieve a desired security posture. While essential for establishing a secure foundation, a baseline itself is a static standard or configuration, not a dynamic metric that measures the performance or efficiency of a security process over time, such as remediation speed. Therefore, it does not directly track operational performance.
- ✗
Key Goal Indicator (KGI)
Why it's wrong here
A Key Goal Indicator (KGI) is a high-level, strategic metric used to determine whether an organization has achieved its overarching business or security objectives. KGIs typically measure outcomes, such as "reduced overall cyber risk by 15%" or "achieved 99.9% system availability," rather than the efficiency of an internal process. Mean time to remediate is an operational metric reflecting process performance, not a direct measure of strategic goal attainment.
- ✓
Key Performance Indicator (KPI)
Why this is correct
A Key Performance Indicator (KPI) is a quantifiable metric used to evaluate the success of a particular activity, process, or project against predefined objectives. Mean time to remediate (MTTR) is an excellent example of a KPI because it directly measures the efficiency and effectiveness of the incident response and vulnerability management processes. Tracking MTTR allows security managers to assess operational performance, identify bottlenecks, and drive continuous improvement in their remediation efforts.
- ✗
Key Risk Indicator (KRI)
Why it's wrong here
A Key Risk Indicator (KRI) is a metric used to provide an early warning signal of increasing risk exposure, helping organizations anticipate and mitigate potential threats before they materialize into incidents. KRIs often track factors like the number of unpatched critical vulnerabilities or employee security awareness scores, which indicate potential future risk. While remediation impacts risk, "mean time to remediate" specifically measures the performance of the remediation process, rather than directly indicating an escalating risk level itself.
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.